93% of organizations still aren't quantum-safe, and the standards have existed for two years

Started by Marnie, Today at 04:18 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: 93% of organizations still aren't quantum-safe, and the standards have existed for two years   Views(Read 27 times)
Active members in this topic:
Marnie(1)

Marnie

DigiCert released its second annual Quantum Readiness Outlook on July 23, surveying 1001 IT and cybersecurity decision makers across the US, UK, and Australia. The headline numbers are stark, 87 percent of organizations report they're planning, testing, or implementing post quantum cryptography, but only 7 percent report that more than half of their digital certificates actually use quantum safe or hybrid cryptography. That's barely two percentage points of improvement from the 5 percent measured back in May 2025.

NIST finalized the first three post quantum cryptographic standards on August 13, 2024, FIPS 203 for lattice based key encapsulation, FIPS 204 for lattice based digital signatures, and FIPS 205 for hash based signatures. These aren't drafts or proposals, they're the same classification of standard that governs AES-256 and SHA-3, and the actual implementations are already available in Chrome 131+, Firefox 135+, and Windows 11 24H2 among others. The excuse that there's nothing to migrate to genuinely expired two years ago.

The concept driving urgency here is harvest now decrypt later, where an adversary records encrypted traffic today with the specific intention of decrypting it retroactively once a capable enough quantum computer eventually exists. At current adoption rates, DigiCert's data suggests only around 15 percent of organizations will be quantum safe by the time NIST's deprecation window opens after 2030, leaving the large majority running encryption that will be officially classified as broken.

Worth noting again that this specific source. Qlosophy, writes in a genuinely alarmist advocacy voice throughout, calling this a present catastrophe unfolding in slow motion and saying the finding should end careers, so I've focused on relaying the actual DigiCert and NIST data points rather than the site's own dramatic framing.

The underlying numbers themselves are real and citable regardless of how the specific source chose to frame them. A huge awareness to deployment gap exists, the standards have been finalized and available for two years, and the current pace of actual migration is nowhere close to fast enough to close that gap before NIST's own stated deadlines
Saving for a trip to Ireland this year.

Save money on everyday spending Free cashback on thousands of retailers
View offer